2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42183 | HIGH | 7.5 | 4.5% | May 5, 2022 | MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/. |
| CVE-2021-42242 | CRITICAL | 9.8 | 1.9% | May 5, 2022 | A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor. |
| CVE-2021-45783 | MEDIUM | 4.6 | 1.9% | May 5, 2022 | Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to... |
| CVE-2021-41739 | CRITICAL | 9.8 | 2.7% | May 5, 2022 | A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cy... |
| CVE-2021-42235 | CRITICAL | 9.8 | 0.9% | May 4, 2022 | SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTic... |
| CVE-2021-43206 | MEDIUM | 4.3 | 0.7% | May 4, 2022 | A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through... |
| CVE-2021-41032 | MEDIUM | 5.4 | 0.5% | May 4, 2022 | An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an ... |
| CVE-2021-41020 | HIGH | 8.8 | 0.6% | May 4, 2022 | An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated,... |
| CVE-2021-20051 | HIGH | 7.8 | 0.7% | May 4, 2022 | SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijac... |
| CVE-2021-32010 | HIGH | 8.1 | 0.2% | May 4, 2022 | Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitat... |
| CVE-2021-42185 | CRITICAL | 9.8 | 1.0% | May 4, 2022 | wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function. |
| CVE-2021-42192 | HIGH | 8.8 | 9.5% | May 4, 2022 | Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to pri... |
| CVE-2021-43164 | HIGH | 8.8 | 34.9% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-43163 | CRITICAL | 9.8 | 2.2% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-43162 | HIGH | 8.8 | 1.8% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-43161 | HIGH | 8.8 | 1.8% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-43160 | HIGH | 8.8 | 1.8% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-43159 | HIGH | 8.8 | 1.9% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-27439 | CRITICAL | 9.8 | 1.4% | May 3, 2022 | TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of... |
| CVE-2021-27435 | CRITICAL | 9.8 | 1.6% | May 3, 2022 | ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitr... |
| CVE-2021-27433 | CRITICAL | 9.8 | 1.6% | May 3, 2022 | ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead ... |
| CVE-2021-27431 | CRITICAL | 9.8 | 1.0% | May 3, 2022 | ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalen... |
| CVE-2021-27427 | CRITICAL | 9.8 | 1.5% | May 3, 2022 | RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead ... |
| CVE-2021-27425 | CRITICAL | 9.8 | 1.5% | May 3, 2022 | Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory as... |
| CVE-2021-27421 | CRITICAL | 9.8 | 0.8% | May 3, 2022 | NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now